CVE-2026-102124 — A Kiteworks appliance setup interface did not enforce authentication once the appliance had completed initial configuration.
Description
A Kiteworks appliance setup interface did not enforce authentication once the appliance had completed initial configuration. An unauthenticated attacker with network access to the appliance could read and modify a limited set of setup records, including a contact name and email address captured during initial configuration.
CVSS v3.1 base metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:NMedium severity
Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.
AV
Network
Attack Vector
AC
Low
Attack Complexity
PR
None
Privileges Required
UI
None
User Interaction
S
Unchanged
Scope
C
Low
Confidentiality
I
Low
Integrity
A
None
Availability
Affected
- Vendor
- accellion
- Product
- kiteworks
Versions
- < 9.5.0
Stated as the source expressed them.
References
Related threats
same CWE or vendorCVE-2026-84249 — IBM Guardium Data Protection 12.2, and 12.2.2 could allow a remote attacker to execute arbitrary management operations due to missing authenticatio…
CVE-2026-84249 · 2h ago
CVE-2026-11318 — Deskin through 3.3.4.3 contains a privilege escalation vulnerability in the com.deskin.service.installer XPC service that allows local unprivileged…
CVE-2026-11318 · 3h ago
CVE-2026-107779 — Dromara Skyeye through commit 003549ae5615bd114ba5bb8ddf6a8e8ead97c321 contains a missing authentication vulnerability in bundled xxl-job-admin Job…
CVE-2026-107779 · 3h ago
CVE-2026-84272 — IBM Guardium Data Protection 12.1 and 12.2.2 are vulnerable to missing authentication in the edge-controller component.
CVE-2026-84272 · 4h ago
CVE-2026-104076 — TVU Networks Receiver/Transceiver devices running firmware before version 7.9 contain a missing authentication vulnerability that allows remote una…
CVE-2026-104076 · 4h ago
PraisonAI: Call API localhost-only authentication bypass via spoofed Host header
CVE-2026-61435 · 5h ago